Bot masters fool with Paris Hilton

18.07.2006
Paris Hilton being exploited? It's hard to believe, but virus writers are becoming more sophisticated in their use of celebrities such as Paris Hilton to entice users to unknowingly install malware.

It may be hard to understand that any users would believe Paris Hilton is inviting them to chat on instant messaging or sending a copy of "that" video via e-mail, but they do - or maybe they're just hopeful.

The IRCbot and IM-Worm-based Kelvir families, made famous by the use of videos and images of Hilton, are becoming more sophisticated, according to antivirus vendor Kaspersky Labs.

To date celebrities, security and law enforcement agencies and politicians have been used to create fast, high-profile infections in devices using IM programs, the company's senior research engineer Roel Schouwenberg said.

But bot masters are now controlling malware distribution and execution by separating the worm from the backdoor.

"The worm will only start spreading when the IRC operator (the bot master) gives a specific command in the channel, or to one specific victim machine," Schouwenberg said. "It should be noted that in such cases, the worm spreads as a link to the backdoor, not to itself."